Identity
Who sponsors and operates the agent, which workload identity acts, and how access is revoked.
BitEvo reviews one coding-agent environment and turns shell, filesystem, Git, MCP/tool and deployment access into an explicit permission map plus a bounded rollout regression suite.
The decision is which actions it may take autonomously, which require confirmation, and which must remain impossible in the agreed environment.
Who sponsors and operates the agent, which workload identity acts, and how access is revoked.
Repository write scope, configuration paths, environment variables, cloud/SSH material and other sensitive locations.
Separate inspection, tests/builds, dependency installs, source mutation, Git mutation, deployment and destructive actions.
Inventory approved and local/private tools, classify consequential actions and check credential/resource binding.
Separate prepare, push, PR, merge and repository-administration authority. Preserve checks and provenance.
Identify SaaS writes, tickets, messages, cloud changes, DNS, deployments, billing and other real-world effects.
The final suite is adapted to the actual agent and Rules of Engagement.
Environment inventory, permission matrix, action/control map, regression results, secure-rollout backlog and team operating rules.
Not endpoint security, not SAST/DAST replacement, not a full penetration test and not a guarantee that unknown defects or bypasses do not exist.
The public intake prepares scope only and must not contain credentials or private repository secrets.
Prepare scope brief